CVE-2007-4216

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
21/08/2007
Last modified:
09/04/2025

Description

vsdatant.sys 6.5.737.0 in Check Point Zone Labs ZoneAlarm before 7.0.362 allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in a METHOD_NEITHER (1) IOCTL 0x8400000F or (2) IOCTL 0x84000013 request, which can be used to overwrite arbitrary memory locations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:checkpoint:zonealarm:*:*:*:*:*:*:*:* 7.0.337.0 (including)
cpe:2.3:a:checkpoint:zonealarm:5.0.63.0:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:zonealarm:6.1.744.001:*:*:*:*:*:*:*